EXPOSURES › CVE-2025-59689
CVE-2025-59689
HIGH ⌖ ON CISA KEV · EXPLOITEDLibraesva Email Security Gateway suffered command injection through e-mail attachments, actively exploited in the wild
Libraesva Email Security Gateway (ESG) allowed attackers to execute arbitrary commands through maliciously crafted email attachments, a flaw actively exploited by cyber actors. This exposed sensitive data and systems to potential compromise.
Shame score — Active exploitation of a critical vulnerability in a widely used product by the DIB, leading to potential unauthorized command execution and data breach risks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.